Korea FreeBSD Users Group News, Internal, Projects, Home
Software, Support, Documentation

Re: ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ-Àç¹ß



[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

[ÀÌÀü ±Û] [´ÙÀ½ ±Û] [ÀÌÀü ´ñ±Û] [´ÙÀ½ ´ñ±Û]


Limiting... Àº ÀÌ ¼­¹ö¿¡¼­ ´Ù¸¥ ¼­¹ö¿¡ Ping ÇÒ ¶§°¡ ¾Æ´Ï¶ó ´Ù¸¥
¼­¹ö¿¡¼­ ÀÌ ¼­¹ö¿¡ pingÀ» ³Ê¹« ¸¹ÀÌ ÇÒ ¶§ ½º½º·Î ÀÀ´ä·üÀ» Á¦ÇÑÇÏ´Â
°ÍÀÔ´Ï´Ù.. Áï °ø°Ý¹Þ°í ÀÖ´Ù°í º¸½Ã´Â °ÍÀÌ ÁÁ°Ú°í¿ä...

ipfw ¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ¸¸é icmp ÆÐŶÀ» ¸ðµÎ ¸·¾Æ º¸¼¼¿ä.

  ipfw add <¹øÈ£> deny icmp from any to any

·ê¼Â ¹øÈ£´Â ±âÁ¸ ±ÔÄ¢ÀÌ ÀÖÀ» °æ¿ì Àû´çÇÑ °÷¿¡ ³¢¿ö³Ö¾î¾ß ÇÕ´Ï´Ù. ipfw
±ÔÄ¢ÀÌ ¾Æ¹«°Íµµ ¾ø´Ù¸é 1000 Á¤µµ ÁÖ½Ã¸é µË´Ï´Ù.

apache¿¡ ½×ÀÌ´Â ·Î±× ¹®Á¦´Â Nimda/Code Red °ø°ÝÀ¸·Î ¸»¾¸µå·È´Âµ¥ ÀÌ
½Ã½ºÅÛÀ̳ª ´Ù¸¥ ½Ã½ºÅÛ¿¡ ÇØ¸¦ ³¢Ä¡Áö ¾Ê½À´Ï´Ù. Windows ½Ã½ºÅÛ¸¸ °ø°ÝÀ»
¹ÞÀ» °¡´É¼ºÀÌ Àֱ⠶§¹®ÀÔ´Ï´Ù.

httpd¸¦ ³»·Á³õ°í, tcpdump µîÀ» »ç¿ëÇØ¼­ ¹«½¼ ÆÐŶÀÌ ¶Ç ¿À°í°¡´ÂÁö
»ìÆìº¸¼¼¿ä.. ±×¸®°í netstat À» »ç¿ëÇØ¼­ ¸ð¸£´Â °÷¿¡¼­ ¿¬°áµÈ °ÍÀÌ
ÀÖ´ÂÁö »ìÆìº¸½Ã±â ¹Ù¶ø´Ï´Ù.

From: Pyun YongHyeon <yongari@kt-is.co.kr>
Subject: Re: ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ-Àç¹ß
Date: Sat, 5 Oct 2002 12:44:13 +0900

> On Fri, Oct 04, 2002 at 03:56:50PM -0700, sammycom wrote:
>  >> ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ-Àç¹ß
>  >> 
>  >> ¹®Á¦µÇ´ø FreeBSD¼­¹ö(66.218.xxx.133)¸¦ ´Ù½Ã ?V¾÷ÇÏ°í³ª¼­ ÀÏÁÖÀϰ£Àº ¸ðµç°Ô Á¤»óÀûÀÎ°Í °°´õ´Ï
>  >> ¶È°°Àº ¹®Á¦°¡ ´Ù½Ã °Ô¼ÓÀϾ´Ï´Ù.
>  >> ¾ÆÆÄÄ¡+ssl ¹®Á¦ÀÎ°Í °°¾Æ¼­ httpd¸¦ ¾Æ¿¹ Á׿©¹ö¸®°í, named ±îÁö Áö¿öµµ ¸¶Âù°¡Áö¿¡¿ä ÀÌ ¼­¹ö¸¸ ³×Æ®¿ö¿¡ ¹°¸®¸é
>  >> ´Ù¸¥ ³ª¸ÓÁöÀÇ ¾ÆÀÌÇÇ ÄÄ(66.218.xx.132) ¿¡¼­µµ default gateway(66.218.xx.1) ±îÁöµµ ÀÎÅͳÝÀÌ ³ª±âÁú ¸øÇÔ´Ï´Ù.
>  >> ±×¸®°í ·Î±×ÆÄÀÏ(/var/log/messages)¿¡ ´ÙÀ½°ú °°Àº ·Î±×°¡ 1Ãʰ£°ÝÀ¸·Î ½×ÀÔ´Ï´Ù.
>  >> ·Î±×ÆÄÀÏ¿¡¸¸ ½×ÀÌ´Â°Ô ¾Æ´Ï°í Äָܼð´ÏÅÍ¿¡ °Ô¼Ó ³ª¿É´Ï´Ù.
>  >> 
>  >> Limiging icmp unreach from 204 to 200 packet per second
>  >> Limiging icmp unreach from 271to 200 packet per second
>  >> Limiging icmp unreach from 231to 200 packet per second
>  >> Limiging icmp unreach from 220to 200 packet per second
>  >> ...(¾ÆÀÌÇÇ ¹øÈ£°°Àº°Å´Â ¾ø±¸¿ä)
>  >> 
> ½Ã½ºÅÛÀÇ ÇØÅ·ÀÌ Àǽɽº·´½À´Ï´Ù.
> 1. ICMP port unreachable code´Â UDP·Î Á¢¼Ó½Ãµµ½Ã ÇØ´ç ¼­¹ö¿¡ ¼­ºñ½º°¡
>    ¾øÀ» °æ¿ì Á¢¼ÓÇÑ ¼­¹ö¿¡¼­ »ý¼ºÇÕ´Ï´Ù.
>    ÇØÅ·µÈ ÈÄ rootkit°°Àº °ÍÀÌ ¼³Ä¡µÇ¾î¼­ ´Ù¸¥ ¿©·¯ ½Ã½ºÅÛÀ» °Ë»çÇϰí ÀÖÀ» °æ¿ì
>    ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
> 
> 2. ÀÌ ½Ã½ºÅÛ¸¸ ¿¬°áÇÏ¸é ´Ù¸¥ ½Ã½ºÅÛµµ networkÀÌ µÇÁö ¾Ê´Â´Ù°í Çϴ°ÍÀ» º¸¸é
>    ¾Æ¸¶µµ ÀÌ ½Ã½ºÅÛ¿¡¼­ network¿¡ »ó´çÇÑ ºÎÇϸ¦ ÁÖ´Â ÀÏÀ» Çϰí ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù.
> 
> °°Àº ¹öÁ¯ÀÇ ±ú²ýÇѽýºÅÛ°ú hash °ªÀ» ºñ±³ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.
> cksum(1), sum(1)Àº È¿°ú°¡ ¾ø°í ¹Ýµå½Ã Cryptographic HashingÀ» »ç¿ëÇØ¾ß ÇÕ´Ï´Ù.
> ´ëÇ¥ÀûÀÎ °ÍÀ¸·Î´Â MD5, RIPEMD160 µîÀÌ ÀÖ½À´Ï´Ù.
> MD5°ªÀº md5(1)³ª openssl(1)·Î ±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù.
> ÃÖ¼ÒÇÑ ´ÙÀ½ÀÇ ÇÁ·Î±×·¥¿¡ ´ëÇØ¼­ ¸ðµÎ °Ë»çÇϰí Çϳª¶óµµ ´Ù¸¥°ÍÀÌ ÀÖ´Ù¸é
> µ¥ÀÌŸ ¹é¾÷ÈÄ ½Ã½ºÅÛÀ» »õ·Î ¼³Ä¡Çϼ¼¿ä.
> 
> ls, ps, ifconfig, md5, openssl, top, netstat,
> sockstat, fstat, sshd, inetd, telnetd, syslogd µî 
> 
>  >> 
>  >> ¾î´ÀºÐ Á¶¾ð´ë·Î °°Àº ¼­ºê³Ý(66.218.32.0/19 : 66.218.32.0 - 66.218.63.255) 
>  >> À» »ç¿ëÇÏ´Â ±× ÁÖº¯µ¿³×(¶Ç´Â) ÀÇ ¹ÙÀÌ·¯½º°¨¿°µÈ Äͧ¹®¿¡ ±×·²¼öµµ ÀÖ´Â°Í °°¾Æ¼­ ISP ¿¡ ¹®ÀÇ, Ç×ÀÇ ÇßÁö¸¸.
>  >> 
>  >> ISP ¿Ð :  ÁøÂ¥·Î ¾î´À ¾ÆÀÌÇÇÀÇ ¹ÙÀÌ·¯½º¶§¹®ÀÎÁö È®ÀÎÇÒ¼öµµ ¾ø´Â »óȲ¿¡¼­ ·Î±×ÆÄÀϸ¸ °®°í¼­ 
>  >> ip¼ÒÀ¯ÇÑ »ç¿ëÀÚ ÀÏÀÏÀÌ ³Ê³× ÄĹÙÀÌ·¯½º¶§¹®¿¡ °°Àº Áö¿ª ´Ù¸¥»ç¿ëÀÚ°¡ ÇÇÇØº»´Ù°í  ÇÒ¼öµµ ¾ø°í ¶Ç °¡°¢ »ç¿ëÀÚÀÇ ¹ÙÀÌ·¯½º ¹®Á¦±îÁö °£¼·Çϰųª È®ÀÎÇÒ¼öÀÖ´Â ¹®Á¦°¡ ¾Æ´Ï¶ó°í ¸¸ ÇÏ´Ï , ±× ¶ÇÇÑ Àϸ®ÀÖ´Â ¸»À̱⵵ ÇÕ´Ï´Ù.
>  >> 
> ¸Â½À´Ï´Ù. ISP°¡ ÃëÇÒ ¼ö ÀÖ´Â Á¶Ä¡¶ó´Â°ÍÀº °ÅÀÇ ¾ø½À´Ï´Ù.
> ±â²¯ÇØ¾ß ISP°¡ °ü¸®ÇÏ´Â ¼­¹öÁß ¹®Á¦ÀÖ´Â ¼­¹öÀÇ ºÐ¸®Á¤µµ ÀÔ´Ï´Ù.
> ÀÌ ¸¶Àúµµ ¸¹ÀÌ ÁÖÀúÇÏ´Â ÆíÀÌÁÒ.
> 
>  >> ±×¸®°í httpd ·Î±×ÆÄÀϺ¸´Ï±î 66.218.xxx.yyy: ....scipt/winnt/cmd.exe ¾î¼±¸ ÇÏ´Â ÁÙÀÌ ²À °°Àº ¼­ºê³Ý¿¡¼­
>  >> µé¾î¿À´Â°Íµµ ÀÖÁö¸¸ 
>  >> 24.xxx.xxx.xxx: : ....scipt/winnt/cmd.exe 
>  >> 206.xxx.xxx.xx. : ....scipt/winnt/cmd.exe 
>  >> ..
>  >> ÀÌ·¸°Ô ÀüÇô ´Ù¸¥ ³×Æ®¿öÅ© ÁÖ¼Ò¿¡¼­µµ µé¾î¿À´õ¶ó±¸¿ä.
>  >> 
>  >> ÀÌ·²¶§´Â ¾î¶»°Ô ÇØ¾ßÇÒÁö ¸ð¸£°Ú³×¿ä
> ÀÌ°Ç ¾î´À¼­¹ö¿¡³ª ÀÖ´Â Á¤»óÀûÀÎ Çö»óÀÔ´Ï´Ù.
> ÀÎÅͳݻ󿡼­´Â ¹ÙÀÌ·¯½º³ª ¿ú¿¡ °¨¿°µÈ ¼­¹öµéÀÌ °ø°Ý´ë»óÀ» Ç×»ó ã°í Àְŵç¿ä.
> ±×¸®°í ÇØÅ°À» °øºÎ(?)ÇÏ´Â Ãʺ¸ÀÚµéÀÌ °ø°ÝÇÁ·Î±×·¥À» ±¸Çؼ­ ½ÃÇèÇϱ⵵ ÇÕ´Ï´Ù.
> 
> -- 
> ============================================================
> // Korea Telecom Internet Solutions, Inc.
> //   FreeBSD/Linux Professional Consulting/Tech. Support
> // 
> // Pyun YongHyeon
> //
> // WWW: http://www.kt-is.co.kr/
> // FTP: ftp://ftp.kt-is.co.kr/
> //
> // TEL: +82-2-364-0400
> // FAX: +82-2-364-9119
> ============================================================
> --
> Please look and take part in KFUG FAQ: <http://www.kr.freebsd.org/FAQ-kr/>
> To Unsubscribe: send mail to majordomo@kr.FreeBSD.org
> with "unsubscribe questions" in the BODY of the message

--
CHOI Junho <http://www.kr.FreeBSD.org/~cjh>
$mail->{"Korea FreeBSD Users Group"} = "cjh at kr.FreeBSD.org";
$mail->{"FreeBSD Committer"}         = "cjh at FreeBSD.org";
$mail->{"Web Data Bank"}             = "cjh at wdb.co.kr";
--
Please look and take part in KFUG FAQ: <http://www.kr.freebsd.org/FAQ-kr/>
To Unsubscribe: send mail to majordomo@kr.FreeBSD.org
with "unsubscribe questions" in the BODY of the message



[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

Copyright © 1998-2005 Korea FreeBSD Users Group.
All rights reserved. webmaster at kr.FreeBSD.org
$Date: 2002/10/31 23:00:24 $
Powered by FreeBSD